HIGH
CVE-2023-33107
CVSS
7.8
KEV
Description
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
Summary dbcve.org
Memory corruption vulnerability in the Linux graphics driver that occurs when assigning a shared virtual memory region during an IOCTL call. The flaw allows a local attacker with low privileges to potentially execute arbitrary code or cause a denial of service via crafted IOCTL requests.
Mitigation
Apply vendor-supplied patches for the Linux graphics driver; update to patched kernel/driver versions. Restrict access to graphics IOCTL interfaces for untrusted users as an interim mitigation.
Weakness (CWE)
CWE-190
Integer Overflow
EPSS Score
0.89%
Probability of exploitation in next 30 days
57.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.